Stored Cross-Site Scripting Vulnerability in ProfilePress Plugin for WordPress
CVE-2024-1535

5.4MEDIUM

Summary

The ProfilePress plugin for WordPress contains a stored cross-site scripting vulnerability that arises from inadequate input sanitization and output escaping of user-supplied attributes in its shortcodes. This flaw allows authenticated attackers with contributor-level or higher permissions to inject malicious scripts that will execute when other users access the affected pages. All versions up to and including 4.15.2 are impacted, making it crucial for site administrators to address this security risk to protect their users from potential exploits.

Affected Version(s)

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress * <= 4.15.2

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Arkadiusz Hydzik
.